| URL: | http://nvidia-research-mingyuliu.com/ |
| Full analysis: | https://app.any.run/tasks/cae15da8-9d65-4555-9756-1d881a910568 |
| Verdict: | Malicious activity |
| Analysis date: | November 23, 2020, 08:27:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | B94A7F0586E3CBDEEF4D9D37BEFDEFCF |
| SHA1: | DFFEF661C90A99848AB04984B1C2324125AD150D |
| SHA256: | C466F66818F3AFF1F0892F17E447889CAE49F287A4C95509D6E95452F136DD69 |
| SSDEEP: | 3:N1KQs+hERZIK:CQsAEzIK |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2544 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "http://nvidia-research-mingyuliu.com/" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.168.131.241:80 | http://nvidia-research-mingyuliu.com/gaugan | US | html | 361 b | malicious |
— | — | GET | 200 | 184.168.131.241:80 | http://nvidia-research-mingyuliu.com/ | US | html | 354 b | malicious |
— | — | GET | 200 | 184.168.131.241:80 | http://nvidia-research-mingyuliu.com/favicon.ico | US | html | 366 b | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/nvidia.png | US | image | 44.8 Kb | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/demo.js | US | html | 11.3 Kb | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/brush_circle.png | US | image | 2.73 Kb | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/eyedropper.png | US | image | 3.54 Kb | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/brush_diamond.png | US | image | 3.12 Kb | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/brush_square.png | US | image | 598 b | malicious |
— | — | GET | 200 | 34.216.122.111:80 | http://34.216.122.111/gaugan/save.png | US | image | 1.73 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 34.216.122.111:80 | nvidia-research-mingyuliu.com | Amazon.com, Inc. | US | unknown |
— | — | 142.250.74.206:443 | clients1.google.com | Google Inc. | US | whitelisted |
— | — | 216.58.205.227:443 | www.google.com.ua | Google Inc. | US | whitelisted |
— | — | 184.168.131.241:80 | nvidia-research-mingyuliu.com | GoDaddy.com, LLC | US | shared |
— | — | 172.217.18.99:443 | www.gstatic.com | Google Inc. | US | whitelisted |
— | — | 216.58.212.131:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
— | — | 172.217.23.142:443 | apis.google.com | Google Inc. | US | whitelisted |
— | — | 184.86.103.208:443 | www.nvidia.com | Akamai Technologies, Inc. | US | suspicious |
— | — | 216.58.212.173:443 | accounts.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.16.142:443 | ogs.google.com.ua | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
nvidia-research-mingyuliu.com |
| malicious |
accounts.google.com |
| shared |
bugs.launchpad.net |
| unknown |
httpd.apache.org |
| whitelisted |
manpages.debian.org |
| suspicious |
ssl.gstatic.com |
| whitelisted |
clients1.google.com |
| whitelisted |
www.google.com.ua |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
— | — | Potentially Bad Traffic | AV POLICY HTTP traffic on port 443 to IP host (POST) |
— | — | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
— | — | Potentially Bad Traffic | AV POLICY HTTP traffic on port 443 to IP host (POST) |
— | — | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
— | — | Potentially Bad Traffic | AV POLICY HTTP traffic on port 443 to IP host (POST) |
— | — | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
— | — | Potentially Bad Traffic | AV POLICY HTTP traffic on port 443 to IP host (POST) |
— | — | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
— | — | Potentially Bad Traffic | AV POLICY HTTP traffic on port 443 to IP host (POST) |